Bugzilla – Bug 1146334
VUL-1: CVE-2017-18550: kernel-source: potential exposure of kernel stack memory because aac_get_hba_info does not initialize the hbainfo structure
Last modified: 2019-08-20 10:06:56 UTC
CVE-2017-18550 An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel before 4.13. There is potential exposure of kernel stack memory because aac_get_hba_info does not initialize the hbainfo structure. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-18550 http://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-18550.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-18550 https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=342ffc26693b528648bdc9377e51e4f2450b4860
all 4.12 branches include the patch. 4.4 branches and older are not affected with the exception of SLE12-SP3 which added/backported the vulnerable function. SLE12-SP3 has also received the fix.